s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

WORDFENCE-07bccf56-99b2-42e6-93ab-606af65e6cac medium

📛 Threat Title

Site5 Various Affected Themes (Various Versions) - Email Spoofing

Category: wordpress-vulnerability Published: Source updated: First seen: Last updated: Source: Wordfence

Description

Various Site5 themes for WordPress are vulnerable to Email Spoofing. This makes it possible for unauthenticated attackers to modify email addresses to potentially perform future attacks on other users. Affected software — theme: boldy (affected: [*, 2.0)); theme: rockwell (affected: *); theme: webfolio (affected: [*, 2.0)); theme: simplo (affected: *); theme: Wise (affected: *); theme: prosume (affected: [*, 2.0)); theme: diary (affected: [*, 2.0)); theme: designpile (affected: *); theme: journalcrunch (affected: [*, 2.0)); theme: alltuts (affected: [*, 2.0)); theme: colorbold (affected: *); theme: xmas (affected: *). CVSS 5.3 (Medium) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (2)

Remediations (12)

  • Wordfence remediation: boldy
    Wordfence

    Update to version 2.0, or a newer patched version

  • Wordfence remediation: rockwell
    Wordfence

    No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.

  • Wordfence remediation: webfolio
    Wordfence

    Update to version 2.0, or a newer patched version

  • Wordfence remediation: simplo
    Wordfence

    No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.

  • Wordfence remediation: Wise
    Wordfence

    No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.

  • Wordfence remediation: prosume
    Wordfence

    Update to version 2.0, or a newer patched version

  • Wordfence remediation: diary
    Wordfence

    Update to version 2.0, or a newer patched version

  • Wordfence remediation: designpile
    Wordfence

    No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.

  • Wordfence remediation: journalcrunch
    Wordfence

    Update to version 2.0, or a newer patched version

  • Wordfence remediation: alltuts
    Wordfence

    Update to version 2.0, or a newer patched version

  • Wordfence remediation: colorbold
    Wordfence

    No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.

  • Wordfence remediation: xmas
    Wordfence

    No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.